Multiple CVEs Affecting Oracle Linux 9 and 10 Released on September 3, 2026

Multiple CVEs Affecting Oracle Linux 9 and 10 Released on September 3, 2026

First seen 3 Sep 2026, 07:00 UTC Linuxsecurity 60.8

Article Content

Browse articles
ThreatCluster

On September 3, 2026, Oracle released multiple security advisories for Oracle Linux 9 and 10, addressing several vulnerabilities across various packages. Key vulnerabilities include CVE-2026-14324 and CVE-2026-14330 in Pipewire, CVE-2026-55194, CVE-2026-67288, CVE-2026-67291, and CVE-2026-67301 in FreeRDP, and CVE-2026-58471 in wget. The advisories highlight buffer overflows and unsafe code practices that could lead to remote code execution or denial of service. Affected systems include Oracle Linux 9 and 10, with patches available for immediate deployment. Security professionals are urged to apply the updates promptly to mitigate potential risks. The advisories emphasize the importance of maintaining up-to-date systems to protect against these vulnerabilities.

Key Points: • Oracle Linux 9 and 10 advisories released on September 3, 2026. • Multiple CVEs including critical buffer overflows and unsafe code practices. • Immediate patching recommended to mitigate risks.

Timeline

2026-07-01
CVE-2026-14324 and CVE-2026-14330 published
Vulnerabilities in Pipewire identified, affecting audio processing on Linux systems.
Linuxsecurity
2026-07-07
CVE-2026-58471 published
Buffer overflow vulnerability in wget disclosed, affecting multiple Linux distributions.
Linuxsecurity
2026-08-01
CVE-2026-67288, CVE-2026-67291, and CVE-2026-67301 published
Multiple vulnerabilities in FreeRDP disclosed, impacting remote desktop functionalities.
Linuxsecurity
2026-08-11
CVE-2026-71217 published
JSON value check vulnerability in iperf3 disclosed, affecting network performance testing.
Linuxsecurity
2026-08-19
CVE-2026-55194 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-03
Oracle releases multiple security advisories
Advisories for Pipewire, FreeRDP, wget, and iperf3 released, urging immediate patching.
Linuxsecurity